Enable job alerts via email!

Principal, Cybersecurity Engineer

Inmar

United States

Remote

USD 130,000 - 180,000

Full time

7 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company in the healthcare domain is seeking a Principal Cybersecurity Engineer to oversee the security and compliance of IT systems. This senior role requires expertise in regulatory adherence, cybersecurity programs, and effective communication with stakeholders. The ideal candidate will have significant experience in healthcare security frameworks, a robust understanding of risk management, and the ability to enhance organizational security posture against evolving threats. This position offers a competitive salary and opportunities for professional growth.

Qualifications

  • 10+ years of experience in security, compliance, or risk management.
  • CISSP, CISM, CRISC, CISA, or similar certification required.
  • Strong knowledge of healthcare regulations including HIPAA and HITRUST.

Responsibilities

  • Develop and manage security strategy for healthcare data.
  • Ensure compliance with healthcare regulations and conduct audits.
  • Collaborate with teams to integrate security best practices in SDLC.

Skills

Incident response
Threat management
Regulatory compliance
Risk management
Cloud security

Education

Bachelor’s degree in Information Security
Master’s degree

Tools

Burp Suite
Metasploit
Elasticsearch
BigQuery

Job description

Job Summary:

The Principal Cybersecurity Engineer is responsible for ensuring the security, compliance, and optimization of the organization’s IT systems and services. This role combines oversight of regulatory compliance—adhering to standards such as HIPAA, HITRUST, and other industry frameworks—with the design, implementation, and maintenance of robust cybersecurity programs. Acting as a technical leader and subject matter expert (SME), the Principal Engineer collaborates across teams to enhance security posture, protect against evolving threats, and support business continuity. This position requires deep expertise in cybersecurity principles, regulatory requirements, and best practices, alongside the ability to communicate effectively with both technical and executive stakeholders.

Key Responsibilities:
  • Security Leadership (20%):

    • Develop, implement, and manage the Healthcare division’s overall security strategy to safeguard sensitive healthcare data, infrastructure, and applications.

    • Collaborate with the enterprise security team on the design and maintenance of security controls, risk management strategies, and incident response protocols.

    • Continuously monitor the security landscape and adapt the company’s security posture to address new threats and vulnerabilities.

  • Compliance Management (20%):

    • Ensure the company’s technology systems and practices comply with healthcare regulations (HIPAA, HITRUST, GDPR, etc.) and maintain all required certifications.

    • Work closely with legal, HR, and operations teams to ensure adherence to internal and external policies governing data privacy and security.

    • Conduct regular compliance audits and assessments to identify gaps and lead initiatives to close them.

  • Collaboration with IT and Engineering Teams (20%):

    • Work with IT, DevOps, and product teams to integrate security best practices throughout the software development lifecycle (SDLC).

    • Implement secure-by-design methodologies in all technology solutions, ensuring that products are built with security from the ground up.

    • Collaborate on infrastructure security, including network architecture, cloud security, and endpoint protection.

  • Risk Assessment & Incident Response (15%):

    • Lead risk assessment efforts across all technology platforms and services, identifying potential threats and vulnerabilities.

    • Develop and maintain a robust incident response plan, ensuring readiness to handle security breaches, data loss, or regulatory incidents.

    • Oversee the investigation of security incidents, including data breaches, and manage the communication process with internal and external stakeholders.

  • Training and Awareness (15%):

    • Develop and implement security awareness programs for all employees, ensuring that security and compliance are ingrained in the company culture.

    • Provide leadership and education on emerging security threats and regulatory changes to senior management and key stakeholders.

  • Regulatory and Client Relationships (10%):

    • Maintain strong relationships with regulatory bodies and clients to ensure transparency and compliance in all data security matters.

    • Serve as the main point of contact for regulatory audits and certifications related to security and compliance.

Qualifications:
  • Bachelor’s degree in Information Security, Computer Science, or a related field. A Master’s degree

  • CISSP, CISM, CRISC, CISA, or similar certification.

  • 10+ years of experience in security, compliance, or risk management, with a focus on healthcare or other highly regulated industries.

  • Strong knowledge of healthcare regulations, including HIPAA, HITRUST, GDPR, and relevant security frameworks (NIST, ISO 27001 PCI DSS, and SOC 2).

  • Proven experience leading security teams and managing compliance programs.

  • Expertise in incident response, threat management, and security operations.

  • Excellent communication skills, with the ability to engage and influence senior leadership and cross-functional teams.

Preferred Skills:

General

  • Experience with cloud security (Google, Azure) and modern DevSecOps practices.

  • Familiarity with healthcare-related cybersecurity threats and defense strategies.

  • Expertise in big data platforms (e.g., Elasticsearch, BigQuery) and security tools (e.g., Burp Suite, Metasploit).

Core Cybersecurity Domains

  • Detection Engineering, Threat Intelligence, and Malware Analysis.

  • Network Security and Monitoring.

  • Security Tool Development and DevSecOps practices.

Advanced Knowledge Areas

  • Secure design principles, database security, cloud computing, and cryptography.

  • Identity and access management, including multi-factor authentication and credential management.

  • Incident management and forensics.

Software Development Security

  • Solid understanding of SDLC, secure coding practices, and DevOps integration.

  • Proficient in identifying and mitigating vulnerabilities, such as privilege escalation and input validation.

We are an Equal Opportunity Employer, including disability/vets.

This position is not eligible for student visa sponsorship, including F-1 OPT or CPT. Candidates must have authorization to work in the U.S. without the need for employer sponsorship now or in the future.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Principal Cybersecurity Engineer – Advanced Cyber Threat Team - Threat Hunter/Intel

Liberty Mutual Insurance

Remote

USD 144,000 - 190,000

8 days ago

Lead Cybersecurity Engineer - Remote inside México

Capgemini

Remote

USD 100,000 - 140,000

14 days ago

Principal Solution Architect (Sales Engineer)

Thales

Bethesda

Remote

USD 135,000 - 222,000

5 days ago
Be an early applicant

Principal Solution Architect (Sales Engineer)

Thales

Remote

USD 135,000 - 222,000

7 days ago
Be an early applicant

Principal Cyber Security Engineer (TS/SCI CI Poly)

GuidePoint Security LLC

Sully Square

On-site

USD 130,000 - 170,000

12 days ago

Lead Cybersecurity Engineer

Anagh Technologies Inc

Charlotte

Remote

USD 100,000 - 140,000

18 days ago

Principal Cybersecurity Engineer

Welch Allyn USA

Remote

USD 104,000 - 143,000

20 days ago

Chief Cyber Security Engineer

Maveris

Washington

Hybrid

USD 150,000 - 190,000

11 days ago

Principal, Cybersecurity Engineer @ Inmar Intelligence

Cyber Crime

North Carolina

On-site

USD 120,000 - 180,000

12 days ago